![Mitel 6800 Series Скачать руководство пользователя страница 192](http://html.mh-extra.com/html/mitel/6800-series/6800-series_administrators-manual_1807020192.webp)
Mitel 6800 Series SIP Phone Release 4.2.0 SP2 Administrator Guide
4-39
User Provided Certificates
The administrator has the option to upload their own certificates onto the phone. The phone
downloads these certificates in a file of .PEM format during boot time after configuration
downloads. The download of the user-provided certificates are based on a filename specified
in the configuration parameter,
https user certificates
(
Trusted Certificates Filename
in the
Mitel Web UI; user-provided certificates are not configurable via the IP Phone UI). The
user-provided certificates are saved on the phone between firmware upgrades but are deleted
during a factory default (or if the configured value in the
https user certificates/Trusted
Certificates Filename
parameter/setting is changed or omitted).
Certificate Validation
Certificate validation is enabled by default. Validation occurs by checking that the certificates
are well formed and signed by one of the certificates in the trusted certificate set. It then checks
the expiration date on the certificate, and finally, compares the name in the certificate with the
address for which it was connected.
If any of these validation steps fail, the connection is rejected. Certificate validation is controlled
by three parameters which you can configure via the configuration files, the IP Phone UI, or
the Mitel Web UI:
•
https validate certificates
- Enables/disables validation.
•
https validate hostname
- Enables/disables the checking of the certificate commonName
against the server name.
•
https validate expires
- Enables/disables the checking of the expiration date on the
certificate.
SSL Certificate Subject Alternative Name (SAN) Support
The 6800 Series SIP phones support Subject Alternative Names (SANs) when validating SSL
certificates. SANs allow Administrators to specify a list of hostnames that can be protected by
a single SSL certificate.
When the "
https validate hostname
" ("
Check Hostnames
" option on the Web UI) is enabled,
the names defined as SANs in a certificate are used for matching against the phone's configured
server name. If no matches are found, the common name in the certificate is used.
The following considerations should be noted:
•
When matching the configured server name against names from the certificate SAN, both
DNS names and IP address names from the SAN are selected. Other names such as the
Service (SRV) record names are ignored.
•
Multiple DNS names and IP address names from the certificate SAN are supported.
Note:
Certificates that are signed by providers other than those listed in
Appendix F,
“Certificates Supported in This Software Release”
do not verify on the phone by default. The
user can overcome this by adding the root certificate of their certificate provider to the
user-provided certificate .PEM file.
Содержание 6800 Series
Страница 1: ...Mitel 6800 Series SIP Phones 58014473 REV02 RELEASE 4 2 0 SERVICE PACK 2 ADMINISTRATOR GUIDE ...
Страница 22: ...Chapter 1 OVERVIEW ...
Страница 53: ...Chapter 2 CONFIGURATION INTERFACE METHODS ...
Страница 72: ...Chapter 3 ADMINISTRATOR OPTIONS ...
Страница 154: ...Chapter 4 CONFIGURING NETWORK AND SESSION INITIATION PROTOCOL SIP FEATURES ...
Страница 264: ...Chapter 5 CONFIGURING OPERATIONAL FEATURES ...
Страница 590: ...Chapter 6 CONFIGURING ADVANCED OPERATIONAL FEATURES ...
Страница 698: ...Chapter 7 ENCRYPTED FILES ON THE IP PHONE ...
Страница 704: ...Chapter 8 UPGRADING THE FIRMWARE ...
Страница 713: ...Chapter 9 TROUBLESHOOTING ...
Страница 743: ...Appendix A CONFIGURATION PARAMETERS ...
Страница 1065: ...Appendix B CONFIGURING THE IP PHONE AT THE ASTERISK IP PBX ...
Страница 1069: ...Appendix C SAMPLE CONFIGURATION FILES ...
Страница 1085: ...Appendix D SAMPLE BLF SOFTKEY SETTINGS ...
Страница 1090: ...Appendix E SAMPLE MULTIPLE PROXY SERVER CONFIGURATION ...
Страница 1094: ...Appendix F CERTIFICATE SUPPORT ...
Страница 1113: ......